PT-2024-29030 · Openstack+2 · Openstack Nova+2

Arnaud Morin

·

Published

2024-07-23

·

Updated

2024-10-30

·

CVE-2024-40767

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OpenStack Nova versions prior to 29.1.1
Description A medium severity issue affects OpenStack Nova, where crafted image paths can expose sensitive data, potentially leading to data theft risk.
Recommendations For OpenStack Nova versions prior to 29.1.1, update to version 29.1.1 or later to resolve the issue.

Exploit

Fix

Files Accessible to External Parties

Weakness Enumeration

Related Identifiers

CVE-2024-40767
DLA-3873-1
GHSA-RM86-H44C-2R2M
RHSA-2024:5083
RHSA-2024:5097
RHSA-2024:5113
USN-6911-1

Affected Products

Linuxmint
Openstack Nova
Ubuntu